CVE-2021-47890 PUBLISHED

LogonExpert 8.1 - 'LogonExpertSvc' Unquoted Service Path

Assigner: VulnCheck
Reserved: 18.01.2026 Published: 23.01.2026 Updated: 23.01.2026

LogonExpert 8.1 contains an unquoted service path vulnerability in the LogonExpertSvc service running with LocalSystem privileges. Attackers can exploit the unquoted path to place malicious executables in intermediate directories, potentially gaining elevated system access during service startup.

Metrics

CVSS Vector: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
CVSS Score: 8.5

Product Status

Vendor Softros Systems
Product LogonExpert
Versions
  • Version 8.1 is affected

Credits

  • Victor Mondragón finder

References

Problem Types

  • Unquoted Search Path or Element CWE